This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Pop-ups, re-directs and web pages very slow to open. [Solved]

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok several problems trying to follow your directions.

My OS is Windows 7 Home Premium.

First… appwiz.clp when copied to run box, then enter, puts me at add/remove programs screen.

There were two Mozilla files there. (1) Mozilla Firefox 49.0.1 (x64 en-US) and (2) Mozilla Maintenance Service.

I uninstalled the first one and the second one appeared to uninstall with it. Went back to unstall the second (maintenance) it and it was already gone.

I see no where the files you metion in RED are.

I then searched the file paths, and still none of these files in RED are present.

Re-boot.

Re-installed FF, but did not have to restore my bookmarks, passwords, home page, or anything else, they were already there.

 

Why?

 

Still have them saved to the desktop (JSON File)unopened.

CPU usage unchanged

 

I’m at a loss here.

Thanks for hanging in there and trying to figure this out.

Await your reply and what about the earlier FF pop-up, was it legit and if I see it again do I try to click it for the patch?

MSE found this yesterday 10/2 it is in "All dectected items"

 

Trojan:Win32/Maltule.C!cl  Alert level severe  Action taken  Removed

Category: Trojan

Recommended action: Remove this software immediately

Items: file:C:\Users\james\AppData\Local\Mozilla\Firefox\Profiles\6uizn1ze.default-1451233910488\cache2\entries\A06FFD07614A9EE64B1E53EEBCC1C033A7AD4A25

You may have to change your settings to be able to locate those entries PLUS the one found by MSE.

 

Show hidden Files and Folders

  • open Windows Explorer, (Windows key+E)
  • at the top, click on Organise, >Folder and search options
  • click on the “View” tab
  • under “Files and Folders”, place a check in Show hidden files, folders and drives

When you've done that can you try to locate the files again.

Followed your directions again to show hidden files and folders, items in red are simply not there.

Saved bookmarks again

Removed firefox again.

Re-installed fire fox and, yet again, bookmarks, passwords, home page still there, did not have to restore.

No changes observed.

Please follow the instructions to backup your bookmarks and passwords again then uninstall Firefox, (do NOT re-install it yet).

Next we’ll see which Firefox files/folders, if any, are left before re-installing it.

===================================================

Please download SystemLook from one of the links below and save it to your Desktop.

SystemLook (32-bit)
SystemLook (64-bit)

  • double-click SystemLook.exe to run it.
  • copy the content of the following codebox into the main textfield - please make sure you include the colon, (:), at the beginning:

    :filefind
    *Mozilla*
    *Firefox*
    
    :folderfind
    *Mozilla*
    *Firefox*
    
    :Regfind
    Mozilla
    Firefox
    
  • click the Look button to start the scan.
  • when finished, a notepad window will open with the results of the scan. Please post this log in your next reply.

Note: The log can also be found on your Desktop entitled SystemLook.txt

Thanks

 

SystemLook 04.09.10 by jpshortstuff
Log created at 11:42 on 05/10/2016 by james
Administrator - Elevation successful

========== filefind ==========

Searching for "*Mozilla*"
C:\$RECYCLE.BIN\S-1-5-21-531013560-757715300-2485835200-1000\$R7NKH0D\u2agdtl9.default-1475535640304\features\{50d290b3-cbc1-4e0c-b3b0-58265f931232}\[removed] –a—- 7076 bytes [13:32 05/10/2016] [23:12 03/10/2016] 095A9E59F9E0DE5C4CA42F46956E8D1B
C:\Users\james\AppData\Roaming\Mozilla\Firefox\Profiles\44vt9ps5.default-1475674360085\features\{0548c0c3-bd7c-421d-a02a-1ca4694dcd0c}\[removed] –a—- 7076 bytes [13:43 05/10/2016] [13:43 05/10/2016] 095A9E59F9E0DE5C4CA42F46956E8D1B
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\Browsers\mozilla.browser –a—- 13262 bytes [02:36 14/07/2009] [21:22 10/06/2009] 9FFA08AA85D403D9CC98CAC2956069AE
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\Browsers\mozilla.browser –a—- 13262 bytes [02:36 14/07/2009] [20:39 10/06/2009] 9FFA08AA85D403D9CC98CAC2956069AE
C:\Windows\winsxs\amd64_netfx-aspnet_regbrowser_files_b03f5f7f11d50a3a_6.1.7600.16385_none_fdde508273949e1f\mozilla.browser –a—- 13262 bytes [20:37 13/07/2009] [20:39 10/06/2009] 9FFA08AA85D403D9CC98CAC2956069AE
C:\Windows\winsxs\x86_netfx-aspnet_regbrowser_files_b03f5f7f11d50a3a_6.1.7600.16385_none_458b87598810c725\mozilla.browser –a—- 13262 bytes [20:46 13/07/2009] [21:22 10/06/2009] 9FFA08AA85D403D9CC98CAC2956069AE
C:\zoek_backup\C_Users_james_AppData_Roaming_Mozilla_Firefox_Profiles_6uizn1ze.default-1451233910488_prefs_20161002_0923_.backup.vir –a—- 29105 bytes [13:23 02/10/2016] [13:23 02/10/2016] 495D4F51A5154960BE02FC9062FA2692

Searching for "*Firefox*"
C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\firefox.com –a—- 893752 bytes [22:58 02/07/2015] [14:48 05/10/2015] E9A75E4B409A01E52055CE7CCA7FF925
C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\firefox.exe –a—- 893752 bytes [22:58 02/07/2015] [14:48 05/10/2015] E9A75E4B409A01E52055CE7CCA7FF925
C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\firefox.pif –a—- 893752 bytes [22:58 02/07/2015] [14:48 05/10/2015] E9A75E4B409A01E52055CE7CCA7FF925
C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\firefox.scr –a—- 893752 bytes [22:58 02/07/2015] [14:48 05/10/2015] E9A75E4B409A01E52055CE7CCA7FF925
C:\Users\james\AppData\Roaming\Microsoft\Office\Recent\Remove Firefox.LNK –a—- 1005 bytes [22:53 03/10/2016] [19:16 04/10/2016] F4F578457E37F5E624FB8FC49C31B63D
C:\Users\james\AppData\Roaming\Microsoft\Windows\Recent\Remove Firefox.lnk –a—- 555 bytes [22:50 03/10/2016] [19:18 04/10/2016] 3E143A05C4296885A7B5BBC110CB4C6D
C:\Users\james\Desktop\Firefox Setup 49.0.1.exe –a—- 45819984 bytes [22:25 03/10/2016] [22:25 03/10/2016] 9A9BD60B081A8C60D6AF673272CA229B
C:\Users\james\Desktop\Remove Firefox.docx –a—- 12079 bytes [22:50 03/10/2016] [22:50 03/10/2016] FE4A771B8D1AFCAEA7049C9C4C829E79
C:\Windows\erdnt\cache86\firefox.exe –a—- 509384 bytes [17:03 02/07/2015] [21:04 22/09/2016] B55A422F81B798459F38D95346E2E6EF
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\Browsers\firefox.browser –a—- 2336 bytes [00:29 19/03/2013] [00:29 19/03/2013] 8E55C3D84FE4E59812B679FCCC8B6061
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\Browsers\firefox.browser –a—- 2336 bytes [22:24 21/03/2013] [22:24 21/03/2013] 8E55C3D84FE4E59812B679FCCC8B6061
C:\Windows\Prefetch\FIREFOX.EXE-18ACFCFF.pf –a—- 59264 bytes [14:29 29/10/2015] [21:28 03/10/2016] ED9D5E93C8B948BCE20C8A1F4DF8686E
C:\zoek_backup\C_Users_james_AppData_Roaming_Mozilla_Firefox_Profiles_6uizn1ze.default-1451233910488_prefs_20161002_0923_.backup.vir –a—- 29105 bytes [13:23 02/10/2016] [13:23 02/10/2016] 495D4F51A5154960BE02FC9062FA2692

========== folderfind ==========

Searching for "*Mozilla*"
C:\Users\james\AppData\Local\Mozilla d—— [17:23 01/07/2015]
C:\Users\james\AppData\Local\Temp\mozilla-temp-files d—— [14:58 05/10/2016]
C:\Users\james\AppData\Roaming\Mozilla d—— [17:23 01/07/2015]

Searching for "*Firefox*"
C:\Users\james\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppHang_firefox.exe_34799d80259d1386161678d4f4acee64b369c38_12a50ffc d—-c- [01:25 25/02/2016]
C:\Users\james\AppData\Local\Microsoft\Windows\WER\ReportArchive\Critical_firefox.exe_63dbec393ea628e9a99f9cb90209328648d6c7b_107c836f d—-c- [01:24 04/11/2015]
C:\Users\james\AppData\Local\Mozilla\Firefox d—— [17:23 01/07/2015]
C:\Users\james\AppData\Roaming\Mozilla\Firefox d—— [17:23 01/07/2015]

========== Regfind ==========

Searching for "Mozilla"
[HKEY_CURRENT_USER\Control Panel\Desktop]
"Wallpaper"="C:\Users\james\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp"
[HKEY_CURRENT_USER\Software\lvmv]
"gsic"="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"IE10"="Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; Trident/6.0)"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"IE9"="Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"IE8"="Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0)"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"IE7"="Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"IE6"="Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"IE10-WP8"="Mozilla/5.0 (compatible; MSIE 10.0; Windows Phone 8.0; Trident/6.0; IEMobile/10.0; ARM; Touch)"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"IE9-WP7"="Mozilla/5.0 (compatible; MSIE 9.0; Windows Phone OS 7.5; Trident/5.0; IEMobile/9.0)"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"IE9-Xbox"="Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0; Xbox)"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"Chrome"="Mozilla/5.0 (Windows NT 6.2) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.52 Safari/536.5"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"Firefox"="Mozilla/5.0 (Windows NT 6.2; rv:12.0) Gecko/20100101 Firefox/12.0"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"IPad"="Mozilla/5.0 (iPad; CPU OS 5_0 like Mac OS X) AppleWebKit/534.46 (KHTML, like Gecko) Version/5.1 Mobile/9A334 Safari/7534.48.3"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"BingBot"="Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\67d6806d_0]
@="{0.0.0.00000000}.{cd49694c-1852-47d3-87ab-c1794ef03957}|\Device\HarddiskVolume2\Program Files\Mozilla Firefox\firefox.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\828d5604_0]
@="{0.0.0.00000000}.{cd49694c-1852-47d3-87ab-c1794ef03957}|\Device\HarddiskVolume2\Program Files (x86)\Mozilla Firefox\firefox.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\c41d6a30_0]
@="{0.0.0.00000000}.{cd49694c-1852-47d3-87ab-c1794ef03957}|\Device\HarddiskVolume2\Program Files (x86)\Mozilla Firefox\plugin-container.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\fab5ab9_0]
@="{0.0.0.00000000}.{cd49694c-1852-47d3-87ab-c1794ef03957}|\Device\HarddiskVolume2\Program Files\Mozilla Firefox\plugin-container.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\fae22d07_0]
@="{0.0.0.00000000}.{cd49694c-1852-47d3-87ab-c1794ef03957}|\Device\HarddiskVolume2\Program Files (x86)\Mozilla Firefox\updated\firefox.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"User Agent"="Mozilla/4.0 (compatible; MSIE 8.0; Win32)"
[HKEY_CURRENT_USER\Software\Mozilla]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\15.0\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\MozillaPlugins]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E239E79D0F3E43448AC9DC382C0BD62]
"68AB67CA7DA73301B744CAF070E41400"="02:\Software\MozillaPlugins\Adobe Reader\Path"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager]
"UserAgent"="Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)"
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla]
[HKEY_LOCAL_MACHINE\SOFTWARE\mozilla.org]
[HKEY_LOCAL_MACHINE\SOFTWARE\mozilla.org\Mozilla]
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows Search\Gathering Manager]
"UserAgent"="Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Mozilla]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Mozilla\Firefox\TaskBarIDs]
"C:\Program Files\Mozilla Firefox"="308046B0AF4A39CB"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\mozilla.org]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\mozilla.org\Mozilla]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"User Agent"="Mozilla/4.0 (compatible; MSIE 8.0; Win32)"
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"User Agent"="Mozilla/4.0 (compatible; MSIE 8.0; Win32)"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"User Agent"="Mozilla/4.0 (compatible; MSIE 8.0; Win32)"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Control Panel\Desktop]
"Wallpaper"="C:\Users\james\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\lvmv]
"gsic"="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"IE10"="Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; Trident/6.0)"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"IE9"="Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"IE8"="Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0)"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"IE7"="Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"IE6"="Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"IE10-WP8"="Mozilla/5.0 (compatible; MSIE 10.0; Windows Phone 8.0; Trident/6.0; IEMobile/10.0; ARM; Touch)"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"IE9-WP7"="Mozilla/5.0 (compatible; MSIE 9.0; Windows Phone OS 7.5; Trident/5.0; IEMobile/9.0)"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"IE9-Xbox"="Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0; Xbox)"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"Chrome"="Mozilla/5.0 (Windows NT 6.2) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.52 Safari/536.5"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"Firefox"="Mozilla/5.0 (Windows NT 6.2; rv:12.0) Gecko/20100101 Firefox/12.0"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"IPad"="Mozilla/5.0 (iPad; CPU OS 5_0 like Mac OS X) AppleWebKit/534.46 (KHTML, like Gecko) Version/5.1 Mobile/9A334 Safari/7534.48.3"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"BingBot"="Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\67d6806d_0]
@="{0.0.0.00000000}.{cd49694c-1852-47d3-87ab-c1794ef03957}|\Device\HarddiskVolume2\Program Files\Mozilla Firefox\firefox.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\828d5604_0]
@="{0.0.0.00000000}.{cd49694c-1852-47d3-87ab-c1794ef03957}|\Device\HarddiskVolume2\Program Files (x86)\Mozilla Firefox\firefox.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\c41d6a30_0]
@="{0.0.0.00000000}.{cd49694c-1852-47d3-87ab-c1794ef03957}|\Device\HarddiskVolume2\Program Files (x86)\Mozilla Firefox\plugin-container.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\fab5ab9_0]
@="{0.0.0.00000000}.{cd49694c-1852-47d3-87ab-c1794ef03957}|\Device\HarddiskVolume2\Program Files\Mozilla Firefox\plugin-container.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\fae22d07_0]
@="{0.0.0.00000000}.{cd49694c-1852-47d3-87ab-c1794ef03957}|\Device\HarddiskVolume2\Program Files (x86)\Mozilla Firefox\updated\firefox.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"User Agent"="Mozilla/4.0 (compatible; MSIE 8.0; Win32)"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Mozilla]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"User Agent"="Mozilla/4.0 (compatible; MSIE 8.0; Win32)"

Searching for "Firefox"
[HKEY_CURRENT_USER\Control Panel\Desktop]
"Wallpaper"="C:\Users\james\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp"
[HKEY_CURRENT_USER\Software\Clients\StartMenuInternet]
@="FIREFOX.EXE"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"Firefox"="Mozilla/5.0 (Windows NT 6.2; rv:12.0) Gecko/20100101 Firefox/12.0"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\67d6806d_0]
@="{0.0.0.00000000}.{cd49694c-1852-47d3-87ab-c1794ef03957}|\Device\HarddiskVolume2\Program Files\Mozilla Firefox\firefox.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\828d5604_0]
@="{0.0.0.00000000}.{cd49694c-1852-47d3-87ab-c1794ef03957}|\Device\HarddiskVolume2\Program Files (x86)\Mozilla Firefox\firefox.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\c41d6a30_0]
@="{0.0.0.00000000}.{cd49694c-1852-47d3-87ab-c1794ef03957}|\Device\HarddiskVolume2\Program Files (x86)\Mozilla Firefox\plugin-container.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\fab5ab9_0]
@="{0.0.0.00000000}.{cd49694c-1852-47d3-87ab-c1794ef03957}|\Device\HarddiskVolume2\Program Files\Mozilla Firefox\plugin-container.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\fae22d07_0]
@="{0.0.0.00000000}.{cd49694c-1852-47d3-87ab-c1794ef03957}|\Device\HarddiskVolume2\Program Files (x86)\Mozilla Firefox\updated\firefox.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\Reading Locations\Document 12]
"File Path"="C:\Users\james\Desktop\Remove Firefox.docx"
[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\User MRU\LiveId_ED545E1B0CF5B88384D061BA9E45E0F8916D1D2B84A21AE824291E5B201E031C\File MRU]
"Item 2"="[F00000000][T01D21E73C2722AE0][O00000000]*C:\Users\james\Desktop\Remove Firefox.docx"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.doc\OpenWithList]
"b"="firefox.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\OpenWithList]
"a"="firefox.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
"Progid"="FirefoxHTML"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\OpenWithList]
"a"="firefox.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
"Progid"="FirefoxHTML"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\OpenWithList]
"d"="firefox.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.js\OpenWithList]
"a"="firefox.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov\OpenWithList]
"a"="firefox.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\OpenWithList]
"c"="firefox.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\OpenWithList]
"c"="firefox.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
"Progid"="FirefoxHTML"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt\OpenWithList]
"b"="firefox.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\OpenWithList]
"a"="firefox.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
"Progid"="FirefoxHTML"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
"Progid"="FirefoxHTML"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xls\OpenWithList]
"b"="firefox.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsx\OpenWithList]
"d"="firefox.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\ftp\UserChoice]
"Progid"="FirefoxURL"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice]
"Progid"="FirefoxURL"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\https\UserChoice]
"Progid"="FirefoxURL"
[HKEY_CURRENT_USER\Software\Mozilla\Firefox]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\15.0\ClickToRun\REGISTRY\MACHINE\Software\Classes\TypeLib\{BDEADEF0-C265-11D0-BCED-00A0C90AB50F}\1.0]
@="Microsoft SharePoint Plug-in for Firefox"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\15.0\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"="Microsoft SharePoint Plug-in for Firefox"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\15.0\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"ProductName"="Microsoft SharePoint Plug-in for Firefox"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\firefox.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Mozilla\Firefox]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Mozilla\Firefox\TaskBarIDs]
"C:\Program Files\Mozilla Firefox"="308046B0AF4A39CB"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"="Microsoft SharePoint Plug-in for Firefox"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"ProductName"="Microsoft SharePoint Plug-in for Firefox"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"="Handles PDFs in-place in Firefox"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"ProductName"="Adobe Reader Plugin for Firefox"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Control Panel\Desktop]
"Wallpaper"="C:\Users\james\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Clients\StartMenuInternet]
@="FIREFOX.EXE"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\IEDevTools\Options\UAString]
"Firefox"="Mozilla/5.0 (Windows NT 6.2; rv:12.0) Gecko/20100101 Firefox/12.0"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\67d6806d_0]
@="{0.0.0.00000000}.{cd49694c-1852-47d3-87ab-c1794ef03957}|\Device\HarddiskVolume2\Program Files\Mozilla Firefox\firefox.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\828d5604_0]
@="{0.0.0.00000000}.{cd49694c-1852-47d3-87ab-c1794ef03957}|\Device\HarddiskVolume2\Program Files (x86)\Mozilla Firefox\firefox.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\c41d6a30_0]
@="{0.0.0.00000000}.{cd49694c-1852-47d3-87ab-c1794ef03957}|\Device\HarddiskVolume2\Program Files (x86)\Mozilla Firefox\plugin-container.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\fab5ab9_0]
@="{0.0.0.00000000}.{cd49694c-1852-47d3-87ab-c1794ef03957}|\Device\HarddiskVolume2\Program Files\Mozilla Firefox\plugin-container.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\fae22d07_0]
@="{0.0.0.00000000}.{cd49694c-1852-47d3-87ab-c1794ef03957}|\Device\HarddiskVolume2\Program Files (x86)\Mozilla Firefox\updated\firefox.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Office\15.0\Word\Reading Locations\Document 12]
"File Path"="C:\Users\james\Desktop\Remove Firefox.docx"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Office\15.0\Word\User MRU\LiveId_ED545E1B0CF5B88384D061BA9E45E0F8916D1D2B84A21AE824291E5B201E031C\File MRU]
"Item 2"="[F00000000][T01D21E73C2722AE0][O00000000]*C:\Users\james\Desktop\Remove Firefox.docx"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.doc\OpenWithList]
"b"="firefox.exe"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
"Progid"="FirefoxHTML"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
"Progid"="FirefoxHTML"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\OpenWithList]
"d"="firefox.exe"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.js\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\OpenWithList]
"c"="firefox.exe"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\OpenWithList]
"c"="firefox.exe"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
"Progid"="FirefoxHTML"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt\OpenWithList]
"b"="firefox.exe"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\OpenWithList]
"a"="firefox.exe"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
"Progid"="FirefoxHTML"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
"Progid"="FirefoxHTML"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xls\OpenWithList]
"b"="firefox.exe"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsx\OpenWithList]
"d"="firefox.exe"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\ftp\UserChoice]
"Progid"="FirefoxURL"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice]
"Progid"="FirefoxURL"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\https\UserChoice]
"Progid"="FirefoxURL"
[HKEY_USERS\S-1-5-21-531013560-757715300-2485835200-1000\Software\Mozilla\Firefox]

-= EOF =-


Wow IE is lightning quick compared to FF!

I'll look at that result as soon as I can but am a bit involved with family stuff tonight so please bear with me.

 

Wow IE is lightning quick compared to FF!

I think you still have an infected file related to Firefox.

On a personal note, I have used IE since it started and still do, (although for some reason I have to use FF to reply at the forums).

I have an XP pc, (I don't use it on the Internet any more much as it's un-patched but use Internet Explorer if and when I do), Win 7, (Internet Explorer), Windows 10, (Microsoft Edge).

Windows-based search engines have never caused a problem for me. Firefox was a good alternative for a while because hackers and other silly people look at attacking the most popular browser, (Internet Explorer), and when FF was suggested to be "safer", people followed and Firefox soon had the same issues.

Google Chrome got targeted because it became 'the in thing' and, before you knew it Chrome caused all sorts of problems. Unfortunately, Google have known about the problems for many years and don't choose to fix them, unlike Microsoft and Mozzilla, whch is why I stick with both.

Getting back to your problem, I'll reply as soon as I can but it will be tomorrow, (GMT - 9 :5pm here now).

Nina

Download and run Junkware Removal Tool

Please download Junkware Removal Tool to your desktop.

  • shut down your protection software now to avoid potential conflicts.
  • run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
  • the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
  • post the contents of JRT.txt into your next message.

===================================================

Run Zoek

For Windows Vista, 7/8/10, right-click Zoek.exe and select: Run as Administrator

  • disable your AntiVirus and AntiSpyware programs so they don’t interfere with the running of Zoek.exe.
  • next, copy/paste the entire script inside the codebox below to the input field of Zoek:
    C:\Users\james\AppData\Roaming\Mozilla;f
    C:\Users\james\AppData\Local\Mozilla;f
    C:\Users\james\AppData\Local\Temp\mozilla-temp-files;f
    ffdefaults;
    emptyFFcache;
    
  • close any open programs/browsers
  • click the Run script button (please be patient - it takes a few minutes to run).

When the tool finishes, the log will open in Notepad.

Note: If a reboot is needed, the log is opened after the reboot.

Please post zoek-results.log and JRT.txt in your reply.

Satchfan

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.9 (09.30.2016)
Operating System: Windows 7 Home Premium x64
Ran by [removed] (Administrator) on Thu 10/06/2016 at 11:29:04.47
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

File System: 8

Successfully deleted: C:\Users\james\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\41S39RY0 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\james\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NW47TNN (Temporary Internet Files Folder)
Successfully deleted: C:\Users\james\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N809LYQ0 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\james\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z5231BGB (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\41S39RY0 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NW47TNN (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N809LYQ0 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z5231BGB (Temporary Internet Files Folder)

 

Registry: 0

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 10/06/2016 at 11:31:51.21
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Using IE to post clipboard replies to this site…is something I’m having difficulty with.

Got the JRT easy enough…, the Zoek results are giving me a problem, as in when I try to either copy and paste from clipboard or attach the txt., I keep getting the message that this forum is not responding.

So the process is completed I just can’t seem able to post the zoek results txt..

The formatting on forums is an issue using IE but there's no reason it shouldn't work at all unless the site was performing some kind of maintenance.

 

If Zoek was completed, try using Firefox again and see what happens.

I have attempted to post the Zoek file many times, I keep getting an error that the post is too long.

However, I have now re-loaded FF and restored the bookmarks (this time I had to).

Upon further review;

Web browsing is back to normal speed.

It appears on of the web site fourums is the culprit.

It loads very slow and also gives me a FF patch update.

It’s the only site that tries to get me to download the patch.

Will not click on that supposed “patch” again.

Everything else seems to be working as it should.

I think we are OK now.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI